You already wrote the standard. Nobody can prove it was followed.
Not the standard itself — you can produce that. The shipment, the file, the decision. What your rule required for that one, what was actually collected against it, and, if something was missing, who let it through anyway and what they were looking at when they did. Most organisations can show the first half and not the second.
Corobate turns the standard you already wrote into the check that runs at the moment the decision is made. When something required is missing it says so then — by name, and by who owes it — instead of at the audit. And every decision afterwards leaves a record your auditor can re-check without trusting us, our servers, or your word.
In this era of AI, a missed risk calculation is a choice
It used to be defensible. Checking whether every document behind a decision was current, from a source that counted, and not contradicted by something else on file — that was hours of work per shipment, and nobody had the hours. So organisations sampled, and trusted, and moved on, and when something surfaced later the honest answer was we could not have caught that at the time.
That answer has an expiry date on it. The work now costs milliseconds. A system can hold every requirement you have ever written, apply all of them to every decision, and say which one was not met — before the goods move, not after the finding. The calculation is no longer the expensive part. Deciding to look is.
Which is why the interesting question is no longer whether you can catch it. It is whether you can show you looked — for this shipment, on this date, against the standard you had actually written down at the time. An organisation that can produce that is in a different position from one that cannot, and the gap between them widens every quarter that the calculation gets cheaper.
Nobody is going to accept we did not know for much longer. The point of this is that you will not have to say it.
Reduce your risks and enforce your requirements
Those are two halves of the same sentence, and most systems only do the first. Reducing risk without enforcing the requirement means flagging things for review — a queue somebody clears under time pressure, where the person clearing it has every incentive to clear it. Enforcing the requirement without reducing risk means a rule so blunt that people route around it, and a rule people route around is a rule that has already failed.
Corobate does both by making them the same act. Your requirement becomes the check — not a policy document somebody was supposed to have read, but the thing that actually runs at the moment the decision is made, on the evidence that is actually on file. When something required is missing or too weak, it does not proceed, and the record names what was missing and who it is owed by, while the truck is still at the dock and the supplier still cares. That is where the risk goes. The gap was always there; the only thing that changed is that you found it in an hour instead of at an audit.
And the requirement stays enforced when nobody is watching, which is the part that is hard. Nothing here can be quietly loosened: every setting can only ever make the test harder, a requirement one authority raises cannot be lowered by another, and if somebody with the standing to do it releases goods anyway, that is a second decision recorded beside the first — with their name on it, what they were shown, and what they put at stake. You are not asking people to be careful. You are making carelessness visible.
The result is a requirement you can prove was applied, a risk you found early enough to do something about, and a record that holds up when somebody who does not trust you asks to see it.
Something your rule required is missing or too weak. It does not proceed — and the record names what was missing and who it is owed by, while there is still time to get it.
It holds, but one document is carrying the whole thing. The record names that one, so the next person does not have to guess which link is thin.
Everything your standard required is present, current, and independently backed for the amount at stake. That is now a fact you can hand to someone.
Some decisions are too big for one person
Above a threshold the operator sets, Corobate will not release a decision until a set number of named, registered people have each signed off on that exact state of the evidence. If the evidence changes afterwards, their sign-offs stop counting — because what they agreed to was that particular set of facts, not the decision in general.
Sometimes you have to move without complete evidence
A named person can accept a known gap in writing, but only when the possible loss falls on them, the amount is bounded, and closing the gap is not cheap and quick. The system calculates the failure rate at which the decision would flip, states it, and asks the person to say whether they believe the real rate is below it. That number, their name, the date, and what they were shown all go on the record.
The checker runs entirely in your browser. Nothing is uploaded, and it works with no network at all — save the page and it still works.
What it does not do
Corobate never reads a document to judge whether its contents are plausible. It knows who said something, how old it is, whether independent parties backed it up, and what happened afterwards. It does not know whether a claim is true, and it never says it does. Anywhere it cannot check something, it says “we could not check this” — which is a real answer, and is never dressed up as a pass.
Is Corobate the right choice for your endeavor?
Quite possibly not, and it is cheaper for both of us to find that out now. Below is the same arithmetic we would do with you in a first meeting. It runs in this page, on your figures, and it is built to tell you no.
Every box below is live — change one and the return, the payback and the break-even recalculate as you type.
This is where the cautious starting figures land, and it is an honest place to begin. Change any box above and every number here recalculates immediately.
- Regulatory fines and enforcement — a finding that becomes a penalty, a consent order, or an import alert.
- Production rhythm — a line, a packhouse or a release train stopping while somebody decides who owns the call.
- Recovery at speed — expedited freight, overtime, a second inspection, re-work against a clock.
- The customer relationship — delisting, audit escalation, a customer-imposed corrective action programme.
- Contractual and insurance — service credits, penalty clauses, deductibles, and what a claims history does to a premium.
- Senior time in an escalation — the hours a recall takes from people whose hours are not $600.
If the answer above clears without any of these, it clears. If it needs them, it does not — and you should not buy on them, because we would be asking you to fund us out of a number neither of us can defend.
Where those figures come from, and what is left out
The arithmetic. Deliveries × error rate = failures. Failures × cost each = the pool. Of that pool, only the paperwork share is addressable, and of that only the share a gate catches. Reconstruction time is counted separately at 80% saved, because a sealed record is already assembled. Pricing is $45,000 a year for the first encoded standard and $25,000 for each additional one, after a $24,000 two-week assessment that is credited in full against your first year.
Four things are deliberately not counted, each of which makes the answer smaller. Brand and reputation damage, which is real and not defensible in a spreadsheet. Penalty avoidance, because it turns on an event that may not happen to you. The value of the signed, priced waiver when somebody releases against the standard anyway. And every loss caused by the product rather than the paperwork — a gate at receiving does not fix a chilled load that ran warm or a batch that was genuinely defective.
Sanity-check the cost per failure against what is published. The large retailers price this exact failure as a share of what you sold them.
| Published | Figure | Source, and their interest |
|---|---|---|
| Walmart, on-time-in-full miss | 3% of COGS | Contractual. Reported 2019; Walmart publishes no numeric threshold itself |
| Target, late or short shipment | 5% of COGS, $150 floor | Contractual. Perfect Order Program, May 2025 |
| Kroger, direct-ship failure | 10% of order value | Contractual, plus a $100 administrative fee |
| Amazon, documentation failures | 3% of cost | Contractual. Rises to 5–6% where advance-ship-notice accuracy falls below 70% |
| Container held on paperwork | $77–154 a day | One Port of Los Angeles terminal tariff, April 2026. Doubles from day five; a refrigerated box gets two free days |
| Origin declared inconsistently with the container route | 2% | Of 5 million import items across 12 EU member states, 2008–2015. European Court of Auditors — a supreme audit institution, and the strongest rate here |
One figure we will not use. You will have seen that the average food recall costs $10 million in direct costs, attributed to a 2011 Grocery Manufacturers Association study. We read it. The figure is not in it — the paper surveyed 36 self-selected members, states no average anywhere, and its survey question asked for total financial impact including lost sales. We mention it so you know which of our numbers we checked.
And once you are running, the same question gets a measured answer
Everything above is an estimate built on your guesses. It is the best anyone can do before they start. After you start, the guessing stops on the half that matters.
Every refusal Corobate makes is a sealed receipt with a reason, a hash and a place in a chain. So the number of refusals is not a claim we make — it is a count anyone can re-derive from your own records without trusting us or you. This panel is what you get from day one, and it is drawing on four real sealed receipts right now.
| Decisions in window | 4 |
| Permitted | 3 |
| Refused | 1 |
| — waived by a named person | 0 |
| Prevented | 1 |
A waived refusal counts as nothing. The movement went out; the record says who chose that. Counting those would be the easiest way to inflate this figure and the first thing an auditor would check.
One fewer prevented refusal and this reads −100%. The swing is larger than the return, which means the sample is carrying the conclusion. The panel says so rather than letting you quote it.
Where to go next
These are in order. Each one answers the question the one before it raises, and the first is the only one that asks anything of you.
-
Build a receipt yourself — 6 steps, about 4 minutes
Set the criteria as a supply-chain manager. Fill the form those criteria produced as the receiving clerk. Watch the gate run and a record seal. Then see the same decision as six different people, and try to forge one of their copies.
The engine is running in the page. Not a video, not a mock-up — the same build the verification harness checks against the server build, decision by decision, across 208 comparisons. If you set rules that refuse your own consignment, that is the product refusing it.
-
One decision, six scoped copies
The walkthrough shows you that each role sees something different. This shows you why the line is drawn where it is — and how a redacted copy is proved faithful without the checker ever seeing what was withheld.
Read this if your first reaction to the walkthrough was “who decides what the inspector sees?”
-
A bank’s supply chain
Four real sealed decisions across a long tail of technology vendors, an automobile remarketing lane and field services. Including the pair worth reading first: the same vendor with the same evidence, minutes apart, at two contract values — one clears, one does not.
Read this if you want to know whether it survives contact with an industry that has no shipments.
-
A NIST-regulated enterprise
NIST publications as the instruments. An AI system refused on its own evaluation reporting F1 0.94, then approved once an independent red team reported 0.89 — a worse number that satisfies a requirement the better one did not.
Read this if you have a control catalogue and a questionnaire, and you have wondered what the questionnaire is worth.
-
How it improves its own judgement
Every figure produced by running the software. A source’s rating usually falls when the system starts measuring it, because a handful of results is weak evidence and the system will not pretend otherwise.
Read this if you have been sold a system that learns, and want to know what a learning loop looks like when it is not allowed to flatter anyone.
-
Check a sealed record
Drop a record in, or paste it. This verifier implements fifteen checks and runs them in your browser; how many of them apply is a property of your record, and the page names any that did not, and why. Change one character and watch it break.
This is the last step because it is the one that matters after you stop reading: nothing above is worth anything if you cannot check it without us.